CVE-2022-24882
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- freerdp/freerdp · fedoraproject/extra packages for enterprise linux · fedoraproject/fedora
- Source
- security-advisories@github.com
References
- https://github.com/FreeRDP/FreeRDP/pull/7750Patch, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/releases/tag/2.7.0Release Notes, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6x5p-gp49-3jhhThird Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/95Exploit, Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AELSWWBAM2YONRPGLWVDY6UNTLJERJYL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOYKBQOHSRM7JQYUIYUWFOXI2JZ2J5RD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWR6KSIKXO4B2TXBB3WH6YTNYHN46OY/
- https://security.gentoo.org/glsa/202210-24Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/pull/7750Patch, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/releases/tag/2.7.0Release Notes, Third Party Advisory
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6x5p-gp49-3jhhThird Party Advisory
- https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/95Exploit, Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/02/msg00034.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AELSWWBAM2YONRPGLWVDY6UNTLJERJYL/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DOYKBQOHSRM7JQYUIYUWFOXI2JZ2J5RD/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PZWR6KSIKXO4B2TXBB3WH6YTNYHN46OY/
- https://security.gentoo.org/glsa/202210-24Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.